IoT firmware penetration testing benchmark
IoT firmware penetration testing benchmark on OWASP IoTGoat, real results only: a static firmware image unpacked to find the backdoor daemon and a Mirai default credential, and a live appliance rooted through an unauthenticated backdoor, each proven with a working exploit.
Darkmoon, the open source autonomous AI penetration testing tool, found 29 IoT vulnerabilities across 2 OWASP IoTGoat runs and proved 4 of them with a real exploit, one from a firmware image alone and one against a live device.
IoT runs, finding by finding
New to the method? Read the IoT firmware penetration testing methodology before the two case studies.
What each run proved
IoT benchmark questions
What does the IoT firmware penetration testing benchmark cover?
How many IoT vulnerabilities did Darkmoon find?
Can Darkmoon test firmware without a physical device?
Darkmoon's own benchmark on the public OWASP IoTGoat lab. The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.